Compliance Program Charter - Texas

Texas Compliance & Regulatory Updated September 19, 2026 Free Word and PDF

COMPLIANCE PROGRAM CHARTER — TEXAS SUPPLEMENT

Company: [________________________________]
Effective Date: [__/__/____]
Approved by: [________________________________]
Version: [____]


TABLE OF CONTENTS

  1. Purpose and Authorization
  2. Texas Regulatory Landscape
  3. Scope — Texas Compliance Domains
  4. Governance Enhancements
  5. Core Program Elements — Texas Focus
  6. Texas Regulatory Change Management
  7. Texas-Specific Reporting and Metrics
  8. Resources
  9. Review and Approval
  10. Annexes

1. PURPOSE AND AUTHORIZATION

This supplement addresses Texas-specific regulatory requirements including the TDPSA (effective July 1, 2024), the Texas breach notification statute, CUBI (biometric identifiers), the DTPA, and the TCHRA.


2. TEXAS REGULATORY LANDSCAPE

Domain Key Texas Statutes Regulator
Privacy & Data Security TDPSA (Ch. 541); Breach notification (§ 521.053); CUBI (§ 503.001) TX AG
Consumer Protection DTPA (Ch. 17); Tex. Bus. & Com. Code TX AG; private plaintiffs
Employment TCHRA (Lab. Code Ch. 21); Texas Payday Law (Lab. Code Ch. 61); Workers' Comp (Lab. Code Title 5) TX Workforce Commission
Financial Services TX Finance Code; TX Dept. of Banking; TX Dept. of Insurance TX Banking Dept.; TDI
Energy/Environmental TX Commission on Environmental Quality (TCEQ); Railroad Commission TCEQ; RRC

3. SCOPE — TEXAS COMPLIANCE DOMAINS

3.1 Privacy and Data Security

☐ TDPSA compliance: consumer rights (access, correction, deletion, portability, opt-out of targeted advertising, sale, profiling); processor obligations; data protection assessments; universal opt-out recognition; sensitive data consent
☐ Breach notification (§ 521.053): individual notice without unreasonable delay and no later than 60 days after determination; electronic AG notice as soon as practicable and no later than 30 days if at least 250 Texas residents are involved (S.B. 768, 2023)
☐ CUBI (§ 503.001): informed consent for biometric identifiers; no sale/disclosure; destruction within 1 year of purpose cessation

3.2 Consumer Protection

☐ DTPA (Ch. 17): prohibition of deceptive trade practices; laundry list of prohibited acts (§ 17.46(b)); treble damages for knowing violations
☐ Marketing, advertising, and sales practice review

3.3 Employment

☐ TCHRA (Lab. Code Ch. 21): discrimination and harassment protections (employers with 15+ employees)
☐ Texas Payday Law (Lab. Code Ch. 61): wage payment requirements
☐ At-will employment considerations

3.4 Biometric Data

☐ CUBI compliance program for any operations involving biometric identifiers
☐ Consent management and destruction tracking


4. GOVERNANCE ENHANCEMENTS

Role Texas Responsibilities
CCO Oversee TX regulatory compliance; TX AG relationship management
Privacy Lead TDPSA compliance; breach notification; CUBI compliance
Consumer Protection Counsel DTPA review; marketing/sales compliance
Employment Counsel TCHRA compliance; wage/hour
Board/Committee Receive TX-specific compliance reports

5. CORE PROGRAM ELEMENTS — TEXAS FOCUS

5.1 Risk Assessment — TX Additions

Risk Area Focus Frequency
TDPSA compliance Consumer rights, processor agreements, DPAs, opt-outs Annual
CUBI compliance Biometric data inventory, consent, destruction schedules Annual
DTPA exposure Marketing claims, disclosures, sales practices Annual
TCHRA employment Discrimination prevention, complaint handling Annual
Breach readiness 60-day notification; AG notification process Annual

5.2 Policies — TX-Specific

☐ TDPSA privacy notice and consumer rights procedures
☐ Texas breach notification procedures (individual notice without unreasonable delay/60-day ceiling; AG electronic notice at 250+ Texas residents/30-day ceiling)
☐ CUBI biometric data policy (consent, retention, destruction)
☐ DTPA marketing/advertising review procedures
☐ TCHRA anti-discrimination/anti-harassment policy

5.3 Training — TX-Specific

Training Audience Frequency
TDPSA privacy awareness Privacy team, customer service Annual
CUBI biometric data handling Employees handling biometric data Annual
DTPA consumer protection Marketing, sales Annual
TCHRA discrimination prevention All TX employees Annual
Breach notification procedures Incident response team Annual

5.4 Monitoring and Testing — TX Additions

☐ TDPSA consumer rights request handling verification
☐ Universal opt-out mechanism testing
☐ CUBI consent tracking and biometric destruction audit
☐ DTPA marketing review
☐ Breach notification tabletop (60-day timeline)
☐ TCHRA complaint tracking

5.5 Third-Party Risk — TX Additions

☐ TDPSA processor agreements for all TX data vendors (§ 541.104(b))
☐ CUBI vendor compliance for biometric data processing
☐ Vendor breach notification SLA alignment with 60-day timeline
☐ Data protection assessment cooperation requirements


6. TEXAS REGULATORY CHANGE MANAGEMENT

Source Monitoring
TX Legislature Track proposed legislation (biennial sessions)
TX AG Monitor enforcement actions and AG opinions
TX Workforce Commission Monitor employment regulatory updates
Courts Track significant TX privacy, consumer, employment decisions

7. TEXAS-SPECIFIC REPORTING AND METRICS

Metric Target Frequency
TDPSA consumer rights compliance Within 45-day statutory deadline Quarterly
Universal opt-out mechanism compliance Verified Annual
CUBI consent documentation 100% coverage Annual
CUBI destruction compliance Within 1 year of purpose cessation Annual
DTPA marketing review All material campaigns Ongoing
Breach notification readiness Tabletop completed Annual
TCHRA training completion 100% of TX employees Annual
Vendor TDPSA processor agreements 100% applicable vendors Quarterly

8. RESOURCES

☐ Privacy team for TDPSA/CUBI
☐ Consumer protection review for DTPA
☐ Employment counsel for TCHRA
☐ External TX regulatory counsel


9. REVIEW AND APPROVAL

Review annually or upon material Texas regulatory change.


10. ANNEXES

Annex A: TX Breach Notification Checklist

☐ Breach determination (date: [__/__/____])
☐ 60-day notification clock starts (§ 521.053)
☐ Affected TX residents identified
☐ Individual notification prepared and sent
☐ If at least 250 Texas residents: TX AG notified electronically as soon as practicable and no later than 30 days after determination (S.B. 768, 2023)
☐ Records retained for AG inspection

Annex B: CUBI Compliance Checklist

☐ Biometric identifier inventory maintained (types: retina/iris scan, fingerprint, voiceprint, hand/face geometry)
☐ Informed consent obtained before capture (§ 503.001(b))
☐ Purpose and duration communicated to individuals before collection
☐ No sale, lease, or disclosure without consent (§ 503.001(c)(1))
☐ Stored with reasonable care, at least same standard as other confidential information (§ 503.001(c)(2))
☐ Destruction within 1 year of purpose cessation (§ 503.001(c)(3))
☐ Retention/destruction schedule documented and maintained
☐ Vendor CUBI compliance verified for biometric data processors
☐ Consent forms retained for audit purposes

Annex C: TDPSA Consumer Rights Compliance Checklist

☐ Privacy notice updated with TDPSA-required disclosures
☐ Consumer rights request intake mechanism operational
☐ Processes verified for all TDPSA rights:

  • Right to confirm processing and access personal data (§ 541.051(b)(1))
  • Right to correct inaccurate personal data (§ 541.051(b)(2))
  • Right to delete personal data (§ 541.051(b)(3))
  • Right to obtain copy in portable format (§ 541.051(b)(4))
  • Right to opt out of targeted advertising (§ 541.051(b)(5)(A))
  • Right to opt out of sale of personal data (§ 541.051(b)(5)(B))
  • Right to opt out of profiling for legal/significant decisions (§ 541.051(b)(5)(C))
    ☐ Response timeline: 45 days (one conditional 45-day extension with timely notice under § 541.052(b))
    ☐ Universal opt-out mechanism recognized (§ 541.055(e))
    ☐ Sensitive data consent mechanisms in place (§ 541.101(b)(4)):

  • Racial/ethnic origin

  • Religious beliefs
  • Mental/physical health diagnosis
  • Sexual orientation
  • Citizenship/immigration status
  • Genetic data
  • Biometric data for identification
  • Children's data (under 13)
  • Precise geolocation
    ☐ COPPA compliance for known-child sensitive data (§ 541.101(b)(4))
    ☐ Data protection assessments completed for the processing listed in § 541.105(a), with the analysis required by subsection (b)
    ☐ Processor agreements include TDPSA-required terms (§ 541.104(b))

Annex D: Texas Regulatory Calendar

Date/Period Event Responsible
Ongoing TDPSA consumer rights requests (45-day response) Privacy
Ongoing Breach notification (60-day deadline from determination) Security / Compliance
Annual CUBI biometric inventory and destruction audit Compliance
Annual TDPSA data protection assessment updates Privacy
Annual DTPA marketing review Consumer Protection Counsel
Annual TCHRA training completion HR / Employment Counsel
Annual Breach notification tabletop exercise Security
Biennial TX Legislative session monitoring Compliance / Legal

Annex E: DTPA Compliance Checklist

☐ Marketing materials reviewed for deceptive trade practices
☐ Product/service representations verified for accuracy
☐ Pricing disclosures complete and not misleading
☐ Warranty and guarantee terms clearly stated
☐ Advertising claims substantiated with documentation
☐ Laundry list violations reviewed (§ 17.46(b)) — including:

  • False representations of goods/services
  • Failure to disclose material information
  • Bait-and-switch practices
  • Unconscionable actions
    ☐ Customer complaint tracking operational for DTPA-related issues

SOURCES AND REFERENCES

  • TDPSA, Tex. Bus. & Com. Code Ch. 541 (eff. July 1, 2024)
  • Tex. Bus. & Com. Code § 521.053 (Breach Notification; 60 Days)
  • Tex. Bus. & Com. Code § 503.001 (CUBI)
  • DTPA, Tex. Bus. & Com. Code Ch. 17
  • TCHRA, Tex. Lab. Code Ch. 21
  • HB 4 (88th Legislature, 2023) — AG enforcement enhancements
  • DOJ Evaluation of Corporate Compliance Programs (Updated September 2024)
  • U.S. Sentencing Guidelines § 8B2.1

This template is provided for informational purposes only and does not constitute legal advice. Consult qualified legal counsel before use.

Insert Image

Insert Table

Watch Ezel in action (sample case)Choose a plan

All changes saved
Save
Export
Export as DOCX
Export as PDF
Generating PDF...
compliance_program_charter_tx.pdf
Ready to export as PDF or Word
AI is editing...
Chat
Review

Draft it in the editor

The AI drafts each section from your answers and you review every word. Drafting from scratch takes hours; finish yours for $99 one time.

  • Built on this template
    Uses the Texas version and the statutes it cites.
  • Formatted like the template
    Captions, numbering and layout stay intact.
  • AI editing
    Rewrite any section from your own notes.
  • Export as PDF and Word
    Yours to review, sign, or file.
Secure checkout via Stripe
Need to customize this document?

About this template

Last updated
September 19, 2026
Jurisdiction
Texas
Category
Compliance & Regulatory

Legal authority

  • U.S. Sentencing Guidelines § 8B2.1
  • DOJ Evaluation of Corporate Compliance Programs (Updated September 2024)
  • Texas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code Ch. 541
  • Tex. Bus. & Com. Code § 521.053 (Breach Notification)
  • Tex. Bus. & Com. Code § 503.001 (CUBI)
  • Texas Deceptive Trade Practices Act (DTPA), Tex. Bus. & Com. Code Ch. 17
  • Texas Commission on Human Rights Act (TCHRA), Tex. Lab. Code Ch. 21
  • SOX § 301, § 806

Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.

Not legal advice

This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.

Checked against the law it cites

The statutes this template relies on are listed under Legal authority.

Tex. Bus. & Com. Code §§ 541.104-.105 (checked September 19, 2026): "A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller. A controller shall conduct and document a data protection assessment of each of the following processing activities involving personal data."

Tex. Bus. & Com. Code § 521.053(b)-(c) (checked September 12, 2026): "A person who conducts business in this state and owns or licenses computerized data that includes sensitive personal information shall disclose any breach of system security, after discovering or receiving notification of the breach, to any individual whose sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure shall be made without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred, except as provided by Subsection (d) or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Any person who maintains computerized data that includes sensitive personal information not owned by the person shall notify the owner or license holder of the information of any breach of system security immediately after discovering the breach, if the sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person."

Tex. Bus. & Com. Code § 521.053(h)-(i) (checked September 12, 2026): "If a person is required by this section to notify at one time more than 10,000 persons of a breach of system security, the person shall also notify each consumer reporting agency, as defined by 15 U.S.C. Section 1681a, that maintains files on consumers on a nationwide basis, of the timing, distribution, and content of the notices. A person who is required to disclose or provide notification of a breach of system security under this section shall notify the attorney general of that breach as soon as practicable and not later than the 30th day after the date on which the person determines that the breach occurred if the breach involves at least 250 residents of this state."

DOJ Evaluation of Corporate Compliance Programs (Updated September 2024) (checked September 5, 2026): "This document is meant to assist prosecutors in making informed decisions as to whether, and to what extent, the corporation’s compliance program was effective at the time of the offense, and is effective at the time of a charging decision or resolution, for purposes of determining the appropriate (1) form of any resolution or prosecution; (2) monetary penalty, if any; and (3) compliance obligations contained in any corporate criminal resolution (e.g., monitorship or reporting obligations)."

Draft your Compliance Program Charter - Texas in the editor

Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.